MCP gets AI agents into your APIs. It doesn’t decide what they should see.
Suppose someone on your operations team wants to ask their AI assistant: “Which orders are going to miss today’s shipping The post MCP gets AI agents into your APIs. It doesn’t decide what they should see. appeared first on The New Stack .
MCP technology enables AI agents to access company APIs, but it doesn't dictate what the agents can see. When an operations team member asks their AI for specific information, such as orders at risk of missing shipping deadlines, the agent requires current data and the ability to update fulfillment systems. To make an internal API accessible to agents, a developer may create an MCP server. However, the agent needs to see only the necessary information without exposing sensitive data or operational details.
Traditional applications handle access control by checking user permissions, processing API calls, and returning appropriate views. But for flexible agents, engineers face a dilemma: filtering responses to protect sensitive information or maintain multiple tools for different teams. A solution is to implement a deterministic, field-level contract that defines precisely what each agent can access, independent of upstream and downstream APIs.
GraphQL, a popular technology, provides a practical way to enforce agentic permissions using field-level contracts. By specifying the exact fields needed, an agent receives only the requested data, avoiding unnecessary exposure of sensitive information. For instance, if an agent requests an order status, the GraphQL server returns only the status and ship date, preventing access to internal fraud scores or customer SSNs.
Read and write operations also follow the same principle. A read mutation allows an agent to request inventory transfers, while a write mutation checks availability and approvals before accepting the request. These permissions are enforced at the field level, ensuring that the upstream APIs remain unchanged.
MCP enables business systems to be accessed by agents, and GraphQL provides the field-level contract to control that access. Companies like Shopify, Netflix, Airbnb, Expedia Group, and Walmart have successfully implemented this model, demonstrating its effectiveness in controlling agentic access to sensitive data.
Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.